SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15487

MEDIUM · CVSS 6.3 EPSS 1.07% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-12 · Last synced 2026-08-11

CyberRota Analysis

AI-Generated

The TRENDnet TEW-821DAP firmware update handler is vulnerable to OS command injection due to improper handling of the Hostname argument, allowing remote attackers to execute arbitrary commands. This vulnerability primarily affects users of the TEW-821DAP model running firmware version 1.11B03, which is no longer supported by the vendor. Organizations still utilizing this outdated hardware should prioritize remediation to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15487
Severity
MEDIUM
CVSS
6.3
EPSS
1.07%

Original NVD Description

A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmware Update Handler. Performing a manipulation of the argument Hostname results in os command injection. The attack may be initiated remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products that are no longer supported by the maintainer.